Security Platform Engineering (Gurugram)

Security Platform Engineering (Gurugram)

14 Aug
|
ITC Infotech
|
Gurugram

14 Aug

ITC Infotech

Gurugram

Strong IAM knowledge across Azure Entra ID, AWS IAM, workload identity, federation, RBAC/ABAC, least privilege, service principals and managed identities/cyberark.

This position will support a hybrid, multi-cloud setting covering Azure, AWS, on-premises platforms, Kubernetes, CI/CD pipelines, and enterprise security controls. The successful candidate must understand both secrets management and IAM end to end, including identities, roles, policies, access models, workload identity, privileged access, service accounts, federation, and audit controls.

The role will involve working closely with development teams in India, UK and Dalian.

Additional support outside India business hours is also required (including working in weekend).

The key responsibilities of this role are:

- Assess current secrets management and IAM practices across Azure, AWS, on-premises, Kubernetes, CI/CD, applications, databases, APIs, and service accounts.
- Define target-state architecture for secrets management, IAM integration, workload identity, privileged access, credential rotation, audit, and governance.
- Create enterprise standards for secrets storage, access, rotation, ownership, naming, tagging, expiry, exception handling, and decommissioning.
- Define when to use centralized secrets platforms versus cloud-native tools such as Azure Key Vault and AWS Secrets Manager.
- Design IAM access models using Azure Entra ID, AWS IAM, roles, policies, groups, service principals, managed identities, OIDC federation, and least-privilege access.
- Support onboarding and migration of application teams from insecure or inconsistent secrets and IAM practices.
- Integrate secrets management with IAM, PAM, CI/CD pipelines, Kubernetes,



databases, APIs, legacy applications, logging, monitoring, and SIEM.
- Help establish operating model components such as ownership, support processes, governance, exception management, control monitoring, and reporting.
- Produce practical documentation, reference architectures, onboarding playbooks, and implementation patterns for engineering teams.

Your skills and experience
- 0-15 years of hands-on experience on below mentioned skills.
- Proven experience delivering at least one enterprise transformation in secrets management, IAM, PAM, DevSecOps, cloud security, or machine identity.
- Strong understanding of IAM concepts, including authentication, authorization, RBAC, ABAC, least privilege, federation, workload identity, privileged access, service accounts, access reviews, and audit controls.
- Hands-on experience with Azure and AWS IAM services, including Entra ID, Azure Managed Identity, service principals, AWS IAM roles, policies, STS, and OIDC.
- Experience with at least two secrets management technologies, such as Azure Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur, Akeyless, Thales CipherTrust, External Secrets Operator, or Secrets Store CSI Driver.
- Experience working in hybrid environments with cloud and on-premises workloads.




- Experience integrating secrets and IAM controls with CI/CD tools such as Azure DevOps, GitHub Actions, Jenkins, GitLab, or similar.
- Ability to define enterprise standards, target-state architecture, migration plans, governance models, and practical engineering patterns.
- Strong stakeholder management skills across security, cloud, platform, infrastructure, application, risk, and audit teams.

Essential skills
- Experience in regulated enterprise environments such as financial services, banking, insurance, healthcare, or similar.
- Experience with CyberArk PAM, HashiCorp Vault Enterprise, machine identity, certificate lifecycle, or dynamic secrets.
- Experience with policy-as-code, Terraform, Azure Policy, AWS Organizations/SCPs, OPA, Sentinel, Checkov, Prisma Cloud, Wiz, or similar tools.
- Experience with secret scanning and remediation using tools such as GitHub Advanced Security, GitGuardian, Gitleaks, TruffleHog, or similar.
- Experience defining dashboards or metrics for secrets compliance, IAM access hygiene, rotation status, onboarding progress, exceptions, and risk reduction.

Personal Skills:
- Able to Set, communicate and manage stakeholder's expectations.
- Ability to prioritize and co-ordinate activities.
- Always open to learn and adopt recent tools/technologies
- Experience of working to tight deadlines on a regular basis.
- Good Analytical and problem solving skills.
- Ability to adapt to changing business needs (Flexible) and learning recent skills quickly.
- Good written and oral communications skills, together with the ability to communicate with management and other business groups.

📌 Security Platform Engineering (Gurugram)
🏢 ITC Infotech
📍 Gurugram

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security platform engineering (gurugram) / gurugram